ImageMagick is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to cause CPU exhaustion, resulting in denial-of-service conditions.
ImageMagick 7.0.7-12 is vulnerable; other versions may also be affected.
Information
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- ImageMagick Homepage (ImageMagick)
- CPU exhaustion in ReadPSDChannelZip #869 (Github)
- Test Case (Github)